Privacy Policy
Effective 2026-05-28
Proxie Innovations Labs Private Limited("Proxie") is the data fiduciary for personal data collected through the Vetra platform. This Policy explains what we collect, why, with whom we share it, and how you exercise your rights under the Digital Personal Data Protection Act, 2023 ("DPDPA") and the Information Technology (Reasonable Security Practices) Rules, 2011.
1. Data we collect
- Account & identity: name, email, phone, role, tenant and clinic assignments.
- Customer-supplied operational data: pet parents, pets, appointments, SOAP notes, prescriptions, inventory and invoices entered by clinic staff. Vetra is a data processor for this category under instructions from the clinic, which is the data fiduciary.
- Authentication metadata: session timestamps, IP address, user-agent, sign-in events.
- Telemetry: error reports, latency metrics, audit-log entries of mutating actions.
2. Purposes & lawful basis
We process the data above to provide and secure the Service, comply with applicable law, enforce these terms, prevent fraud, and improve product quality. The lawful basis under the DPDPA is performance of the contract with the clinic and our legitimate interests in security and product operation.
3. Sub-processors
We engage the following sub-processors. Each is bound by data-protection commitments at least as protective as this Policy:
- Microsoft Azure — application hosting (Southeast Asia region).
- Supabase (PostgreSQL + Auth) — primary database with row-level security, identity provider.
- GitHub Container Registry — image artefact storage.
An up-to-date list is provided on request to privacy@proxie.in.
4. International transfers
Primary data residency is Southeast Asia. Limited operational telemetry may be processed outside India by our sub-processors. Where this happens, we rely on the sub-processor's contractual safeguards.
5. Retention
Customer Data is retained for the life of the subscription plus a 30-day export window, after which it is deleted or anonymised. Audit logs are retained for up to 24 months. Backups are rotated on a 30-day cycle.
6. Security
We follow the practices described in the Security Statement: TLS in transit, encryption at rest, row-level security policies in the database, RBAC at the application layer, principle of least privilege for staff access.
7. Your rights under DPDPA
You have the right to:
- access and obtain a copy of your personal data,
- request correction of inaccurate personal data,
- request erasure (subject to legal retention requirements),
- withdraw consent where processing is consent-based,
- nominate another person to exercise these rights on your behalf, and
- register a grievance with the Data Protection Board of India.
Direct requests to privacy@proxie.in. We respond within 30 days.
8. Cookies
We use strictly necessary cookies for authentication (Supabase session) and locale (next-intl). We do not use third-party advertising or analytics cookies on the application surface.
9. Children's data
The Service is not directed at children under 18 and we do not knowingly collect their personal data.
10. Grievance officer
For complaints under the IT Act and DPDPA, contact our grievance officer at privacy@proxie.in or by post at Plot No. 563 & 564, Nirvana, Chandigarh Road, Kohara, Ludhiana, Punjab — 141112. We respond within 30 days as required by Rule 4 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
11. Changes
We will post material changes to this Policy at least 30 days before they take effect.